Overview
IEC TR 62351-13:2016 - part of the IEC 62351 series on power systems data and communications security - provides guidelines for security topics that should be covered in standards and specifications used in the power industry. It is aimed at standards and specification developers, not at prescribing implementation-level security controls. The report frames a checklist approach so that the combination of standards and specifications used in any system implementation collectively addresses essential cybersecurity topics.
Key Topics and Requirements
The Technical Report organizes guidance across four primary areas (summarized from its clauses):
-
Security requirements for users and applications (Clause 5)
- Risk assessment, security policies, roles and authorization
- User-focused procedures and accountability (policy, training, access control)
-
ICT cryptographic techniques (Clause 6)
- Best practices for specifying cryptography (selection, lifecycle, and applicability)
- Key management (including public-key approaches), multicast/group key considerations
- Device and platform integrity, secure network configuration, Internet and wireless cryptography
- Network and system management, defence‑in‑depth, security testing and interoperability
-
Engineering design and configuration management for grid resilience (Clause 7)
- Integration of cyber security into system engineering and planning
- Design strategies for resilience, monitoring, centralized analysis, testing, and training
-
Correlation with information exchange standards and OSI layers (Clause 8)
- Mapping security requirements to OSI layers and to relevant IEC communications standards
- Guidance on ensuring complementary standards collectively mitigate threats
The report emphasizes that some standards should focus on policy/organizational controls while others implement technical (“bits and bytes”) measures - together they must form a complete security posture.
Practical Applications and Intended Users
IEC TR 62351-13 is a practical reference and checklist for:
- Standards committees and specification authors drafting power‑industry standards
- Utilities, system integrators and equipment vendors validating that combined standards cover required security topics
- Security architects and compliance teams mapping requirements across protocols, devices and organizational practices
- Certification and regulatory bodies assessing completeness of security coverage in deployments
Use cases include scoping new standards, reviewing existing specifications for gaps (policy, cryptography, engineering), and aligning security across the OSI stack.
Related Standards and Context
- Part of the IEC 62351 series (data and communications security for power systems)
- References IEC TS 62351-2 (glossary) and maps security needs to IEC communications standards and OSI layers
- Intended as guidance, not prescriptive implementation rules - best used as a checklist to ensure comprehensive coverage of cybersecurity topics across standards.